Skip to content
Tech News
← Back to articles

CISA: Medusa ransomware hit over 500 critical infrastructure orgs

read original more articles
Why This Matters

The rise of Medusa ransomware targeting over 500 critical infrastructure organizations underscores the increasing cyber threats facing essential sectors. This highlights the urgent need for enhanced cybersecurity measures to protect vital services and sensitive data from sophisticated ransomware attacks, which can have widespread societal and economic impacts.

Key Takeaways

The Cybersecurity and Infrastructure Security Agency (CISA) said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021.

This was revealed in a joint advisory in coordination with the Department of Health and Human Services (HHS) and the Federal Bureau of Investigation (FBI).

"As of April 2026, Medusa actors have impacted more than 500 victims across multiple critical infrastructure sectors, including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services," they said.

"Other victims include organizations in the medical, education, legal, insurance, technology, and manufacturing industries."

This is an update to a joint report published in March 2025, which said the Medusa ransomware operation had impacted an estimated over 300 critical infrastructure organizations.

The three federal agencies recommended that network defenders secure their networks against the ransomware group's attacks by mitigating security vulnerabilities to protect operating systems, software, and firmware from exploitation attempts.

Security teams are also advised to segment networks to block lateral movement after compromise and to block access from untrusted origins to remote services on internal systems.

Active since January 2021

The Medusa ransomware operation surfaced five years ago, in January 2021. Still, the gang's activity only picked up in 2023 after launching the Medusa Blog leak site and began using stolen data as leverage to pressure victims into paying ransoms.

Medusa emerged as a closed ransomware variant, but it evolved into a Ransomware-as-a-service (RaaS) operation and adopted an affiliate model.

... continue reading